Newsletter 13/02/2023

This machine contains a web application built with Sinatra that is vulnerable to command injection, which leads to Remote Code Execution (RCE). The user has sudo
permissions to run a Bash script that is vulnerable to PATH
hijacking, which can be used to escalate privileges

Cross-Site Scripting. Insecure Direct Object Reference

Firefox files inspection. Credentials decryption

Word macros deobfuscation

Windows RDP image recovery

PCAP analysis. XOR cipher

Core file analysis. Memory inspection. AES encryption